Back to home
Subprocessors
Last updated: May 14, 2026
The third-party service providers ("subprocessors") that Chask uses to operate the Service. For full context, see our Privacy Policy — this page is the authoritative source for who receives what data.
Current subprocessors
OpenAI
- Purpose:
- LLM provider for goal breakdown, planning, milestones, chat, and content generation. Models: gpt-5.3-codex, gpt-4o, gpt-4o-mini.
- Data shared:
- Goal content, task descriptions, chat messages, About-me profile context, persona traits (when enabled), milestone structure, scheduling windows, story extracts.
- Processing location:
- United States
- Transfer mechanism:
- Standard Contractual Clauses; OpenAI API customer data is not used to train models by default.
Supabase
- Purpose:
- Primary database, authentication, real-time, and file storage.
- Data shared:
- Account profile, goals, tasks, milestones, journal notes, workspace data, OAuth tokens (encrypted at rest).
- Processing location:
- United States (AWS)
- Transfer mechanism:
- Standard Contractual Clauses
Sentry
- Purpose:
- Error monitoring and performance tracing.
- Data shared:
- Stack traces, request paths, IP address, browser metadata, Chask context tags (UUIDs). Authorization headers, cookies, and goal/NLP request bodies are scrubbed before send.
- Processing location:
- United States
- Transfer mechanism:
- Standard Contractual Clauses; EU-US Data Privacy Framework
PostHog
- Purpose:
- Product analytics (opt-in only). Autocapture and session recording are disabled.
- Data shared:
- Aggregated feature-usage events, page views, opt-in event metadata.
- Processing location:
- United States or European Union (depending on cluster)
- Transfer mechanism:
- Standard Contractual Clauses; EU-US Data Privacy Framework
Google (Calendar OAuth)
- Purpose:
- Calendar integration: read and write events you authorize.
- Data shared:
- OAuth refresh and access tokens (encrypted at rest with AES-256-GCM); calendar event payloads you authorize.
- Processing location:
- United States; Google global infrastructure
- Transfer mechanism:
- EU-US Data Privacy Framework; Standard Contractual Clauses
Stripe
- Purpose:
- Payment processing and subscription management.
- Data shared:
- User ID, workspace ID, selected tier, billing amount, Stripe customer ID. Card numbers are never sent to Chask.
- Processing location:
- United States
- Transfer mechanism:
- Standard Contractual Clauses; EU-US Data Privacy Framework
Resend
- Purpose:
- Transactional email delivery (verification, password resets, account notifications).
- Data shared:
- Recipient email address, sender, subject, message body.
- Processing location:
- United States
- Transfer mechanism:
- Standard Contractual Clauses
Redis-compatible cache
- Purpose:
- Short-lived caching of AI responses to reduce LLM calls (default TTL 30 minutes).
- Data shared:
- Request keys derived from input parameters; generated AI outputs.
- Processing location:
- United States (co-located with primary infrastructure)
- Transfer mechanism:
- Internal infrastructure; no third-party transfer
Notification of changes
We update this page whenever we add, change, or remove a subprocessor. To receive change notifications by email, contact privacy@chask.ai with the subject line "Subscribe to subprocessor change notifications".
For Data Processing Agreements with Chask, email legal@chask.ai.